logo

Hackers begin mass-exploiting Ivanti VPN zero-day flaws

ID: e464bbec-2c2f-57b4-8a60-52bf9c0fb549

STIX ID: report--e464bbec-2c2f-57b4-8a60-52bf9c0fb549

Feed Name: TechCrunch Security News

Threat Score
90/100

Date Published: 2024-01-16

Date Updated: 2026-04-23

Author: Carly Page

...
...

Security researchers report mass exploitation of two zero-day vulnerabilities in Ivanti Connect Secure VPN appliances (CVE-2023-46805, CVE-2024-21887), attributed to China-backed APT activity (UTA0178 and additional groups), with evidence of at least 1,700 compromised devices worldwide across critical sectors; Ivanti has yet to publish patches and advises mitigations while researchers warn that public proof-of-concept code could broaden impacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.